> Markdown version of [/jobs/ext/156440-rmf-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/156440-rmf-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # RMF Information System Security Officer - **Company:** Inc. (osi) - **Location:** San Antonio, TX, United States - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Identity and Access Management, Information Security Management, Open Systems Interconnection (OSI), Public Key Infrastructure, Security Content Automation Protocol, Software Vulnerability Management, Information Technology - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b2f78cc5f9559a1b ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, This is a hands-on technical role. You need to be able to work independently in eMASS and run ACAS scans from day one., * Active Secret clearance * DoD 8570.01-M IAT Level II certification (Security+, CISSP, CCNA Security, GSEC, or equivalent) * Hands-on eMASS experience, managing controls and accreditation records independently * Hands-on ACAS and HBSS experience * Familiarity with RMF policy: DoDD 8500.1, DoDI 8500.2, DoDI 8510.01, NIST SP 800-53 * Experience with Industrial Security programs and NISPOM compliance * Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience) Preferred * Experience supporting PKI or IdAM systems * Vulnerability management program experience including policy development and metrics tracking ## Description Osi Vision is seeking an experienced ISSO to support the Air Force Public Key Infrastructure (PKI) System Program Office. You will own the RMF lifecycle for PKI and Air Force Identity and Access Management (IdAM) systems, maintaining accreditation packages, conducting compliance scans, and working directly alongside a government counterpart to keep systems authorized and secure., * Own and manage RMF packages in eMASS to achieve and maintain Authority to Operate (ATO) and Approval to Connect (ATC) * Conduct compliance scans using ACAS, SCAP, and AF-approved tools; document and track findings in the POA&M * Apply and validate STIGs across system components; coordinate SCA-V assessments * Develop and maintain System Security Plans, Incident Response plans, and supporting artifacts * Assist the FSO with implementation and management of the facility Security Program per NISPOM (32 CFR Part 117) and DAAPM * Identify and document local threats and vulnerabilities; report indicators into the Insider Threat process * Brief stakeholders on security posture, schedule updates, and compliance status * Conduct periodic self-inspections and ensure corrective action on all findings ## Related Videos - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)